Anonymous
2026-07-22 04:16:01
(22 minutes ago)
Web attack
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 02:13:11
(1 day ago)
Web attack
Bad Web Bot
Web App Attack
Anonymous
2026-07-18 20:02:10
(3 days ago)
Web attack
Bad Web Bot
Web App Attack
Anonymous
2026-07-14 14:02:57
(1 week ago)
Web attack
Bad Web Bot
Web App Attack
Anonymous
2026-07-12 16:02:55
(1 week ago)
Web attack
Bad Web Bot
Web App Attack
Anonymous
2026-06-06 16:02:03
(1 month ago)
Web attack
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-01 03:01:32
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 83.229.106.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 83.229.106.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 23:01:24.180686 2026] [security2:error] [pid 12707:tid 12715] [client 83.229.106.64:45013] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.kettlehill.com"] [uri "/.svn/wc.db"] [unique_id "ahz2BPr1zQOtbkd9viU3pAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-01 20:16:52
(4 months ago)
(mod_security) mod_security (id:212620) triggered by 83.229.106.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 83.229.106.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 15:16:44.228211 2026] [security2:error] [pid 32106:tid 32115] [client 83.229.106.64:43221] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.staging.kettlehill.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /?post_type=post&s=\\x22><script>alert(/3amikq3kpqximil8w0ylapxwfw3/)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.staging.kettlehill.com"] [uri "/"] [unique_id "aaSerMyHAVRioPijSO93UQAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
MAGIC
2025-12-12 02:24:59
(7 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-12-01 05:47:50
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 83.229.106.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 83.229.106.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 00:46:55.666801 2025] [security2:error] [pid 26090:tid 26458] [client 83.229.106.64:46207] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.kettlehill.com"] [uri "/.env.old"] [unique_id "aS0rzwqR0geke5MRGl4CgwAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-17 12:14:26
(8 months ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-01 16:53:27
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 83.229.106.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 83.229.106.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 12:53:24.464719 2025] [security2:error] [pid 30109:tid 30126] [client 83.229.106.64:36177] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.kettlehill.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.kettlehill.com"] [uri "/wp-login.php.bak"] [unique_id "aN1chJmcYLK3QOnvb--H-gAAAYo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπ¬
raramos
2025-08-07 19:00:07
(11 months ago)
[SMB remote code execution attempt: port tcp/445]
in blocklist.de:'listed [pop3]'
in SpamCop:'listed ...
show more
[SMB remote code execution attempt: port tcp/445]
in blocklist.de:'listed [pop3]'
in SpamCop:'listed'
in sorbs:'listed [web], [spam]'
in Unsubscore:'listed'
*(RWIN=8192)(04:10)
show less
Web Spam
Email Spam
Port Scan
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-01 07:33:40
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 83.229.106.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 83.229.106.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 03:33:33.873732 2025] [security2:error] [pid 3331489:tid 3331572] [client 83.229.106.64:34459] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.staging.kettlehill.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.staging.kettlehill.com"] [uri "/wp-login.php.bak"] [unique_id "aIxtzTqSEPOvsBY_LS5iZwAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-01 07:03:26
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 83.229.106.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 83.229.106.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 03:03:00.112158 2025] [security2:error] [pid 2749697:tid 2749817] [client 83.229.106.64:43243] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.net"] [uri "/..../..../..../..../..../..../..../..../..../windows/win.ini"] [unique_id "aDv7JGzUxJS8AZi9Bz3XQwAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack